AI is not only being used to improve processes and work smarter. Major technology companies are reporting that the same technology is now also being deployed by cybercriminals. They are using AI to make phishing emails more credible, to improve malware faster, and to scale up attacks with less technical knowledge. That sounds alarming, but it is primarily a signal that the playing field is changing.
For Flemish and European SMEs, this is no reason for panic, but rather an invitation to approach digital resilience more consciously. After all, the same technology attackers use can help your company detect risks faster and manage them better. In this blog, we examine what is happening, the impact this has on people and organizations, and how you can already make sensible choices regarding AI and cybersecurity today.
What exactly is going on
A major technology company warns that AI is increasingly being deployed in cyberattacks. According to their analyses, AI helps, among other things, to:
- to make phishing messages more credible in multiple languages;
- to debug and improve malware code faster;
- to automate attacks, so that less technical expertise is required.
AI acts here as a “force multiplier”: existing attack techniques do not necessarily become new, but they do become faster, cheaper, and more accessible. The core message is that cybercriminals use the same generally available AI tools as ordinary companies. A clear trend is pointed out, not one specific incident. Importantly: this concerns a shift in efficiency and scale, not entirely new forms of digital threat.
Impact on people and society
For people in organizations, this means that digital attacks will start to feel more human. A phishing email full of errors is relatively easy to recognize. An email rewritten by AI, in flawless Dutch and with correct context regarding your sector, is far less so. As a result, the pressure on employees increases: they are being approached more frequently and in a smarter way.
For organizations – especially SMEs – the challenge is shifting. Whereas previously the focus was primarily on the “technical wall” (firewalls, antivirus, software updates), the combination of people, processes, and technology is now becoming decisive. Training, clear procedures, and a clear incident plan are becoming just as important as tools.
At a societal level, this raises questions about trust in digital communication. What do you still believe in your mailbox, on social media, or in messages supposedly from a colleague? At the same time, it offers opportunities to deal with AI in a mature way: through transparent agreements, better digital literacy, and collaboration between companies, governments, and technology partners.
Ethical and sustainable considerations
The use of AI in cyberattacks touches directly on ethics and responsibility. Technology in itself is neutral, but the way it is deployed is not. Some key dimensions:
- Ethics & honestyAI lowers the threshold for doing harm. This places extra responsibility on technology providers as well as on companies that deploy AI. Which models do you offer? How do you prevent abuse where possible?
- TransparencyOrganizations must be able to clearly explain which AI systems they use, which data is processed, and which security measures are in place. This applies both internally (to employees) and externally (to customers and partners).
- SafetySecurity by design is becoming a basic requirement. AI solutions that improve processes must be designed from day one with strong access control, logging, encryption, and data minimization.
- Bias & fair useSecurity systems that use AI must not unfairly disadvantage groups of people (for example, through incorrect risk profiles). Fair and representative data are essential.
- Sustainability & energyLarge AI models consume energy. Unnecessary, poorly thought-out experiments cost not only money but also increase the ecological footprint. By building targeted, efficient AI applications—that create real value and reduce risks—you avoid waste.
An ethical and sustainable AI strategy therefore looks beyond “does it work technologically?”. It asks: is it fair, safe, explainable, and in line with our values as an organization?
Safety and risk dimension
The combination of AI and cyberattacks entails a number of concrete risks:
- Hacking & automated attacksAI can help scan for vulnerabilities and develop better-packaged malware. Attackers can iterate and test faster.
- Data leaks: as soon as an attacker is inside, AI can be deployed to search through large amounts of data, classify it, and select the most “interesting” pieces for theft or blackmail.
- PrivacyLeaked data often contains personal data. This directly impacts GDPR, reputation, and trust. Moreover, AI can help build profiles, which increases the risk of misuse of personal information.
- Abuse of AI in your own organizationEmployees can unknowingly paste sensitive data into public AI tools (for example, customer data or source code), causing information to end up outside your control.
The core issue is: AI primarily changes the speed, scale, and credibility of attacks. The solution is not “not using AI,” but conscious governance. Think of policies regarding the use of AI, technical security layers, and a culture in which employees feel safe to report suspicious situations immediately.
What does this mean for your business?
For Flemish and European SMEs, it boils down to this: AI is becoming a permanent part of the digital landscape – on both the attacker and defense sides. Your challenge is to deploy AI for process improvement without weakening your digital resilience.
That starts with a sober risk assessment. Which processes do you want to support with AI? Which data is involved? What happens if that data is leaked or manipulated? And how does this align with GDPR, NIS2, and other relevant regulations in Europe?
In addition, there is the human aspect. When you introduce AI tools (chatbots, decision support, automation), you also change how employees work. This requires training, clear agreements, and a realistic understanding of what AI can and cannot do. Employees remain your first line of defense – especially in a world with increasingly convincing phishing and social engineering.
Finally, collaboration is crucial. SMEs do not have to do this alone. By working with partners who combine AI, software development, and cybersecurity, you can build secure, efficient, and future-proof solutions step by step.
3 concrete recommendations for SMEs
- 1. Create a clear AI and security policy
Establish which AI tools may and may not be used, which types of data may never be included in public models, and how you handle access rights and logging. Ensure that this policy is simple and understandable for all employees. - 2. Combine training with realistic tests
Invest in short, practical training courses on phishing, password management, and safely handling AI. Supplement this with periodic simulations (e.g., phishing tests) to measure where the risks lie and where extra guidance is needed. - 3. Build AI solutions with security-by-design
When deploying AI for process improvement, incorporate security and privacy from the start. Consider data minimization, encryption, role-based access, and clear audit trails. Preferably work with European partners who comply with GDPR and local regulations.
Conclusion: technology at the service of people
AI in cyberattacks is not science fiction, but neither is it a reason for doom. It is a signal that our digital environment is maturing. Companies that consciously address ethics, security, and sustainability in their AI strategy today are building long-term trust.
At Canyon Clan, we believe that technology only has true value when it makes people stronger – not more vulnerable. We help SMEs design AI and software solutions that improve processes and are secure, transparent, and future-proof. Would you like to explore how your company can leverage AI without compromising your digital resilience? Feel free to contact us for an exploratory conversation.
